Legal & compliance centre

HLD Group

Personnel security policy

Screening, employment terms, and termination procedures.

Last updated: 24 July 2026

Version 1.0 · Review cycle: 365 days · View all frameworks

1. Purpose

This policy defines the security measures applied across the employment lifecycle — before, during, and after engagement — to reduce the risk of human error, misuse, and insider threat, while respecting the rights of personnel.

2. Scope

This policy applies to all employees, contractors, and other personnel with access to HLD Group systems, facilities, or data, and is applied consistently with applicable employment, privacy, and anti-discrimination law.

3. Before engagement — screening

Background verification is conducted proportionate to the role and the sensitivity of access, in accordance with applicable law and with the individual’s consent. Roles involving privileged access, customer data, or defence work may require enhanced checks, including where relevant government security clearance.

  • Identity and right-to-work verification
  • Employment and qualification checks appropriate to the role
  • Criminal record checks where lawful and role-appropriate
  • Enhanced screening and clearances for sensitive and defence-related roles

4. During engagement

  • Terms of employment and contracts include security, confidentiality, and acceptable-use obligations
  • Personnel acknowledge applicable policies and complete required training
  • Access follows least privilege and is adjusted as roles change
  • A disciplinary process addresses security policy violations fairly and consistently

5. Insider risk

HLD Group manages insider risk proportionately and lawfully through least-privilege access, segregation of duties, monitoring of privileged activity, and a supportive culture in which concerns can be raised under the Whistleblower and Speak-Up Policy. Monitoring is conducted transparently and within the limits of applicable privacy and employment law.

6. Termination and change of role

  • Access is revoked promptly on termination, coordinated between People and Culture, IT, and resource owners
  • Company assets and data are returned or securely removed
  • Ongoing confidentiality and other post-employment obligations are confirmed
  • Access is re-evaluated on any change of role

7. Framework alignment

  • ISO/IEC 27001:2022 Annex A controls 6.1 to 6.6 (people controls)
  • NIST SP 800-53 Rev. 5 control family PS (Personnel Security)
  • SOC 2 Trust Services Criteria CC1.4 and CC1.5
  • Applicable employment, privacy, and anti-discrimination law

8. Roles, exceptions, and review

People and Culture and the CISO jointly own personnel security. Exceptions require documented approval. This policy is reviewed at least annually and applied consistently with local law.

Related frameworks

For contractual attestations or audit packs, contact [email protected].